STIGQter STIGQter: STIG Summary: Apple iOS/iPadOS 26 Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 13 May 2026:

Apple iOS/iPadOS 26 must require a valid password be successfully entered before the mobile device data is unencrypted.

DISA Rule

SV-278784r1150599_rule

Vulnerability Number

V-278784

Group Title

PP-MDF-993300

Rule Version

AIOS-26-010400

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Install a configuration profile to require a password to unlock the device.

Configuration Profile Key: forcePIN

Check Contents

Review configuration settings to confirm the device is set to require a passcode before use.

This procedure is performed on the iOS and iPadOS device.

On the iPhone and iPad:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the Configuration Profile from the iOS management tool containing the password policy.
5. Tap "Restrictions".
6. Tap "Passcode".
7. Verify "Passcode required" is set to "Yes".

If "Passcode required" is not set to "Yes", this is a finding.

Vulnerability Number

V-278784

Documentable

False

Rule Version

AIOS-26-010400

Severity Override Guidance

Review configuration settings to confirm the device is set to require a passcode before use.

This procedure is performed on the iOS and iPadOS device.

On the iPhone and iPad:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the Configuration Profile from the iOS management tool containing the password policy.
5. Tap "Restrictions".
6. Tap "Passcode".
7. Verify "Passcode required" is set to "Yes".

If "Passcode required" is not set to "Yes", this is a finding.

Check Content Reference

M

Target Key

5723